Bringing HSTS to Google.com

Ink

Administrator
Thread author
Verified
Jan 8, 2011
22,318
2
55,055
8,379
Bringing HSTS to www.google.com
Posted by Jay Brown, Sr. Technical Program Manager, Security


"To further protect users, we've taken another step to strengthen how we use encryption for data in transit by implementing HTTP Strict Transport Security—HSTS for short—on the www.google.com domain. HSTS prevents people from accidentally navigating to HTTP URLs by automatically converting insecure HTTP URLs into secure HTTPS URLs. Users might navigate to these HTTP URLs by manually typing a protocol-less or HTTP URL in the address bar, or by following HTTP links from other websites.

Preparing for launch

Ordinarily, implementing HSTS is a relatively basic process. However, due to Google's particular complexities, we needed to do some extra prep work that most other domains wouldn't have needed to do. For example, we had to address mixed content, bad HREFs, redirects to HTTP, and other issues like updating legacy services which could cause problems for users as they try to access our core domain.

Deployment and next steps

We’ve turned on HSTS for www.google.com, but some work remains on our deployment checklist."​

Continue reading.
 
Thanks for the share :)

By curiosity :oops: , I have just tested with hxxp://www.google.fr

=> hxxps://www.google.fr/?gws_rd=ssl

I have looked all the requests and HSTS appears on requests for :

- hxxps://apis.google.com/.../

=> and When I clicked on "connection" :

- hxxps://accounts.google.com/ServiceLogin?hl=fr&passive=true&continue=hxxps://www.google.fr/

An affair to follow !
 
Last edited: